Roles & permissions

Who can do what

Three roles — Owner, Manager and Employee. Each one knows exactly what it can touch.

Owner

Whoever set the shop up. Full run of the place — staff, shifts, closed days, settings, billing, and everyone's hours.

  • Sets up and runs the shop
  • Adds, edits and removes staff
  • Sets up every rule and setting
  • Makes someone a Manager
  • Looks after billing and the plan

Manager

Espresso

A trusted member of staff the Owner promotes. The Owner picks exactly which parts they can run — it's never all or nothing.

  • A separate switch per manager for staff, shifts, closed days, leave and hours
  • A new Manager starts with leave and hours, nothing else
  • Shop settings, billing, sub-QR codes and promoting managers stay Owner-only
  • Still checks in and out like anyone else

Employee

Somebody on the floor, linked to the shop. Checks in, sees their own hours, asks for time off.

  • Checks in and out by scanning the QR code
  • Sees their own hours
  • Asks for time off, a full day or part of one
  • Cancels their own request while it's still waiting
  • Sees their own shift and the closed days

The whole list

Who can do what, line by line

Every action, every role. No surprises.

Always allowedOwner decides, per managerNot available
Action
Employee
Manager
Owner

Today

See their own day
Employee: Always allowedManager: Not availableOwner: Not available
See the whole day (everyone on it)Employee: Not availableManager: Comes from manage_attendanceOwner: Always allowed
See today's numbersEmployee: Not availableManager: Always allowedOwner: Always allowed
See how much leave is waitingEmployee: Not availableManager: Always allowedOwner: Always allowed

Hours

Check in and out by QR code
Employee: Always allowedManager: Always allowedOwner: Always allowed
See their own hoursEmployee: Always allowedManager: Always allowedOwner: Always allowed
See everyone's hoursEmployee: Not availableManager: Comes from manage_attendanceOwner: Always allowed
Fix a day's hoursEmployee: Not availableManager: Comes from manage_attendanceOwner: Always allowed
Take a day off the recordEmployee: Not availableManager: Comes from manage_attendanceOwner: Always allowed
Add a missed day by handEmployee: Not availableManager: Comes from manage_attendanceOwner: Always allowed
Clock a colleague in or outEmployee: Owner decides, per managerManager: Comes from canCheckInOthersOwner: Not available

Leave

Ask for their own time off
Employee: Always allowedManager: Always allowedOwner: Always allowed
Put in leave for anyoneEmployee: Not availableManager: Comes from manage_leaveOwner: Always allowed
See their own leaveEmployee: Always allowedManager: Always allowedOwner: Always allowed
See everyone's leaveEmployee: Not availableManager: Comes from manage_leaveOwner: Always allowed
Approve or turn down leaveEmployee: Not availableManager: Comes from manage_leaveOwner: Always allowed
Cancel their own leave while it's waitingEmployee: Always allowedManager: Always allowedOwner: Always allowed
Cancel anyone's leaveEmployee: Not availableManager: Comes from manage_leaveOwner: Always allowed

Staff

Add someone to the team
Employee: Not availableManager: Comes from manage_employeesOwner: Always allowed
Edit someone's detailsEmployee: Not availableManager: Comes from manage_employeesOwner: Always allowed
Remove someone (their hours stay)Employee: Not availableManager: Comes from manage_employeesOwner: Always allowed
Give out or take back a check-in cardEmployee: Not availableManager: Comes from manage_employeesOwner: Always allowed
Take back a registered phoneEmployee: Not availableManager: Comes from manage_employeesOwner: Always allowed
Excuse someone from a check-in ruleEmployee: Not availableManager: Comes from manage_checkin_exemptionsOwner: Always allowed
Link or unlink a loginEmployee: Not availableManager: Not availableOwner: Always allowed
Make someone a Manager, or undo itEmployee: Not availableManager: Not availableOwner: Always allowed
Change what a Manager can doEmployee: Not availableManager: Not availableOwner: Always allowed

Shifts and closed days

See the shifts
Employee: Always allowedManager: Always allowedOwner: Always allowed
Create, edit and delete shiftsEmployee: Not availableManager: Comes from manage_shiftsOwner: Always allowed
Set different hours each dayEmployee: Not availableManager: Comes from manage_shiftsOwner: Always allowed
See the closed daysEmployee: Always allowedManager: Always allowedOwner: Always allowed
Create, edit and delete closed daysEmployee: Not availableManager: Comes from manage_closuresOwner: Always allowed

The shop and its settings

See the shop's details
Employee: Always allowedManager: Always allowedOwner: Always allowed
Rename the shopEmployee: Not availableManager: Not availableOwner: Always allowed
Set up shop WiFi onlyEmployee: Not availableManager: Not availableOwner: Always allowed
Set up one phone per personEmployee: Not availableManager: Not availableOwner: Always allowed
Set up near the shop onlyEmployee: Not availableManager: Not availableOwner: Always allowed
Set up NFC tap check-inEmployee: Not availableManager: Not availableOwner: Always allowed
Set up card check-inEmployee: Not availableManager: Not availableOwner: Always allowed
Make or revoke an API keyEmployee: Not availableManager: Not availableOwner: Always allowed
Pair a kioskEmployee: Not availableManager: Not availableOwner: Always allowed
Make or edit sub-QR codesEmployee: Not availableManager: Not availableOwner: Always allowed
Delete the shopEmployee: Not availableManager: Not availableOwner: Always allowed

Billing

See the current plan
Employee: Always allowedManager: Always allowedOwner: Always allowed
Move up or down a planEmployee: Not availableManager: Not availableOwner: Always allowed
Look after the payment cardEmployee: Not availableManager: Not availableOwner: Always allowed

How this is enforced, underneath

There are four levels. Every request is checked against them before anything happens.

VIEWOwner, Manager, Employee

Read-only on the shop's data. Everyone linked to the shop gets this.

CAPABILITYOwner, and a Manager per permission

The named capabilities — manage_employees, manage_shifts, manage_closures, manage_leave, manage_attendance — handed out one at a time to each Manager. The Owner holds all of them without being given them.

EDIT / DELETE on WorkspaceOwner only

Rename or delete the shop, change settings, look after billing, mint sub-QR codes, promote managers.

PER-QR MANAGERA Manager put over a sub-QR

Adds hours and leave authority over that QR's own staff, on top of anything they already hold shop-wide.

Note: Each capability is handed over on purpose, one manager at a time. A Manager with only manage_leave can approve leave but can't edit the staff list. A Manager with everything except manage_attendance still sees only their own hours. The same check runs on every API endpoint, so there's no way round it.

Espresso: up to 2 managers
Double Espresso: unlimited managers
Free plan: just the Owner

Ready to set up your team?

Create your shop, add your staff, and hand a bit of it to the people you trust.